Feat: Updating the Privacy Providers, moving them into the appropriate Modules, Updating Privacy views
This commit is contained in:
@@ -19,9 +19,25 @@ use Modules\Core\Privacy\DTOs\UserSubject;
|
||||
* itself is left alone (any completed order it produced is handled separately by
|
||||
* OrderDataProvider, which is what retention law actually cares about) — only its
|
||||
* address PII is removed.
|
||||
*
|
||||
* Also covers Cart.meta's own PII-adjacent keys — Modules\Core\Checkout\Services\
|
||||
* CheckoutService::setRecoveryConsent()/selectPaymentMethod() write
|
||||
* recovery_consent/recovery_consent_at/recovery_consent_policy_version and
|
||||
* payment_method/checkout_fingerprint directly onto this same Cart row, which the
|
||||
* address-only erase above never touched. Kept Customer-scope, consistent with
|
||||
* how Cart itself is already classified — see docs/privacy.md for the
|
||||
* User-vs-Customer discussion this raised.
|
||||
*/
|
||||
class CartDataProvider implements PersonalDataProvider
|
||||
{
|
||||
private const META_KEYS = [
|
||||
'recovery_consent',
|
||||
'recovery_consent_at',
|
||||
'recovery_consent_policy_version',
|
||||
'payment_method',
|
||||
'checkout_fingerprint',
|
||||
];
|
||||
|
||||
public function name(): string
|
||||
{
|
||||
return 'carts';
|
||||
@@ -29,18 +45,26 @@ class CartDataProvider implements PersonalDataProvider
|
||||
|
||||
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||
{
|
||||
$addresses = CartAddress::whereIn('cart_id', Cart::where('customer_id', $subject->customerId)->pluck('id'))->get();
|
||||
$carts = Cart::where('customer_id', $subject->customerId)->get();
|
||||
|
||||
return new ProviderExportResult('carts', $addresses->map(fn (CartAddress $address) => [
|
||||
'type' => $address->type,
|
||||
'first_name' => $address->first_name,
|
||||
'last_name' => $address->last_name,
|
||||
'line_one' => $address->line_one,
|
||||
'city' => $address->city,
|
||||
'postcode' => $address->postcode,
|
||||
'contact_email' => $address->contact_email,
|
||||
'contact_phone' => $address->contact_phone,
|
||||
])->all());
|
||||
$addresses = CartAddress::whereIn('cart_id', $carts->pluck('id'))->get();
|
||||
|
||||
return new ProviderExportResult('carts', [
|
||||
'addresses' => $addresses->map(fn (CartAddress $address) => [
|
||||
'type' => $address->type,
|
||||
'first_name' => $address->first_name,
|
||||
'last_name' => $address->last_name,
|
||||
'line_one' => $address->line_one,
|
||||
'city' => $address->city,
|
||||
'postcode' => $address->postcode,
|
||||
'contact_email' => $address->contact_email,
|
||||
'contact_phone' => $address->contact_phone,
|
||||
])->all(),
|
||||
'carts' => $carts->map(fn (Cart $cart) => [
|
||||
'id' => $cart->id,
|
||||
'meta' => $this->metaOnly($cart),
|
||||
])->all(),
|
||||
]);
|
||||
}
|
||||
|
||||
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||
@@ -50,7 +74,19 @@ class CartDataProvider implements PersonalDataProvider
|
||||
|
||||
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||
{
|
||||
CartAddress::whereIn('cart_id', Cart::where('customer_id', $subject->customerId)->pluck('id'))->delete();
|
||||
$carts = Cart::where('customer_id', $subject->customerId)->get();
|
||||
|
||||
CartAddress::whereIn('cart_id', $carts->pluck('id'))->delete();
|
||||
|
||||
foreach ($carts as $cart) {
|
||||
$meta = (array) $cart->meta;
|
||||
|
||||
foreach (self::META_KEYS as $key) {
|
||||
unset($meta[$key]);
|
||||
}
|
||||
|
||||
$cart->update(['meta' => $meta]);
|
||||
}
|
||||
|
||||
return new ProviderErasureResult('carts', ErasureOutcome::Erased);
|
||||
}
|
||||
@@ -59,4 +95,14 @@ class CartDataProvider implements PersonalDataProvider
|
||||
{
|
||||
return new ProviderErasureResult('carts', ErasureOutcome::Skipped, 'Carts belong to Customer accounts, not individual users.');
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array<string, mixed>
|
||||
*/
|
||||
private function metaOnly(Cart $cart): array
|
||||
{
|
||||
$meta = (array) $cart->meta;
|
||||
|
||||
return array_intersect_key($meta, array_flip(self::META_KEYS));
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user